▸ BLOG
Blog
Research, advisories, hardware hacking, and the occasional rant. Subscribe via RSS.
2026
-
We just decided to do it: bringing BSides Maine to life
How a group chat and a logo became Maine's first BSides: 260 attendees, 50+ talk submissions, and a nonprofit's worth of paperwork.
-
CVEase: disclosure tracking that doesn't live in your head
A free, open-source desktop app that tracks coordinated disclosure from first vendor contact through to the published advisory.
2025
-
Keeping DC207 afloat
What it actually takes to run a DEF CON Group: finding speakers, wrangling venues, covering costs, and all the work nobody sees behind a free meetup.
-
HatGPT: a rude offline AI that lives in a hard hat
A sarcastic, fully offline AI chatbot running on a Raspberry Pi inside a construction hard hat, shouting into the DEF CON Meshtastic mesh.
2024
-
How to have the most fun at DEF CON
Advice for enjoying DEF CON instead of merely surviving it: solder a badge, talk to the person next to you, and stop trying to optimize the con.
2023
-
DC207's response to SecureMaine: allyship and cyber inclusivity
Why DC207 did not take part in SecureMaine, and what allyship asks of a security community when a conference partners with an anti-LGBTQIA+ organization.
-
DEF CON 31: The Lonely Hard Drive, and a very large Betty Pagefile
Running The Lonely Hard Drive at DEF CON 31: handing strangers free hard drives loaded with a CTF, and everything that took to pull off.
2022
-
How to set up your very own AND!XOR Chomper hacker smartwatch
A step-by-step build guide for setting up and flashing the AND!XOR Chomper, the DEF CON 30 badge that turns a LilyGO T-Watch into a hacker smartwatch.
-
Student Loan Scams - Info & Informational Resources
How student loan forgiveness scams work, how to check who is really calling you, and free posters and graphics to help warn other people.
-
Beckman Coulter's Remisol Advance - Security Advisory MARBAS-22-001
Six CVEs in Beckman Coulter's Remisol Advance lab middleware: insecure service permissions let any unprivileged user overwrite executables running as SYSTEM.
-
Bypass .NET Request Validation with MSSQL
Getting past .NET request validation on old web forms by letting MSSQL reassemble the characters the filter wouldn't let you send.
-
The IT Industry Needs a Toxic Masculinity Intervention
Corporate IT has a masculinity problem, it is driving good people out of technology, and pretending otherwise is not working. A rant with receipts.
2021
-
CVE-2021-22521 - The ZEN of Privilege Escalation
An unquoted service path in Micro Focus ZENworks that hands an attacker SYSTEM on an affected host, and how the disclosure played out.
-
CVE-2021-32077 - Fun With Social Security Numbers
A healthcare credentialing platform exposed practitioner Social Security numbers. How CVE-2021-32077 was found, and what it says about medical software.
2019
-
Your passwords are up for grabs. Here's how security researchers find them.
How researchers dug through the 2019 dump of 770 million leaked credentials to find real passwords, and why the method no longer works.